WPB Circliful Security & Risk Analysis

wordpress.org/plugins/wpb-circliful

This plugin will add a responsive Circliful. Very easy to use, just put a shortcode.

10 active installs v1.0 PHP + WP 3.3+ Updated May 11, 2014
circlifuldatashow-percent
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPB Circliful Safe to Use in 2026?

Generally Safe

Score 85/100

WPB Circliful has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "wpb-circliful" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The code analysis reveals no instances of dangerous functions, raw SQL queries, unescaped output, or file operations. Furthermore, there are no external HTTP requests, which mitigates risks associated with remote code execution or data exfiltration. The plugin's entry points, primarily a single shortcode, are not immediately flagged for missing authentication or capability checks, indicating a potentially well-secured interface. The absence of any recorded vulnerabilities, including CVEs, in its history further reinforces this positive assessment, suggesting a history of stable and secure development.

While the static analysis paints a promising picture, the absence of taint analysis results (0 flows analyzed) means that potential vulnerabilities arising from complex data sanitization or insecure handling of user-supplied data may not have been detected. Similarly, the lack of explicit nonce and capability checks mentioned, while not necessarily a direct concern if the shortcode itself doesn't handle sensitive data or actions, leaves room for potential issues if its functionality evolves or is used in unexpected contexts. The limited attack surface is a positive, but the lack of granular security checks on the single entry point is a minor point of attention.

In conclusion, "wpb-circliful" v1.0 appears to be a secure plugin with good coding practices evident in its current state. The absence of known vulnerabilities and the clean static analysis are significant strengths. However, the lack of comprehensive taint analysis and the potential for unspecified security checks on its shortcode mean that continued vigilance and thorough testing, especially with future updates, are advisable. The plugin demonstrates a good foundational security but could benefit from explicit checks on its entry points to ensure robustness.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WPB Circliful Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPB Circliful Release Timeline

v1.01
v1.0Current
Code Analysis
Analyzed Mar 17, 2026

WPB Circliful Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WPB Circliful Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpb-circliful] main.php:116
WordPress Hooks 8
actioninitmain.php:17
actionwp_enqueue_scriptsmain.php:25
actioninitmain.php:37
actionwp_footermain.php:51
actioninitmain.php:82
actioninitmain.php:118
actioninitmain.php:122
filtercmb_meta_boxeswpb_metaboxes.php:66
Maintenance & Trust

WPB Circliful Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 11, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings5
Active installs10
Developer Profile

WPB Circliful Developer Profile

WPBean

26 plugins · 39K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect WPB Circliful

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpb-circliful/css/jquery.circliful.css/wp-content/plugins/wpb-circliful/css/font-awesome.min.css/wp-content/plugins/wpb-circliful/css/main.css
Script Paths
/wp-content/plugins/wpb-circliful/js/jquery.circliful.min.js
Version Parameters
wpb-circliful/css/jquery.circliful.css?ver=wpb-circliful/css/font-awesome.min.css?ver=wpb-circliful/css/main.css?ver=wpb-circliful/js/jquery.circliful.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
cir_areacir_single
Data Attributes
data-dimensiondata-textdata-infodata-widthdata-fontsizedata-percent+3 more
JS Globals
jQuery
Shortcode Output
<div class="cir_area"><div class="cir_single"><div id="myStat"
FAQ

Frequently Asked Questions about WPB Circliful